Eyal Marcus / Copilot Training for Financial Services
DORA Article 13(6) & 5(4) · Updated: September 2026

Copilot Training for
Financial Services,
Documented for DORA.

Bottom line: book a live Copilot lecture or workshop for your bank, insurer or investment firm, and walk away with an attendance record and a training log mapped to DORA Article 13(6) and Article 5(4). Copilot training for financial services does not make Copilot "DORA compliant" (no product is). It is the documented control your ICT risk framework is required to have around the rollout.

This is not legal advice (I'm a Copilot trainer, not a lawyer). Talk to your own compliance and legal team about how DORA applies to your organisation. What I can do is build the training your staff and management body already owe, and hand you the paperwork that proves it happened.

90 minExecutive Briefing
264AI sessions delivered
112Organisations
17 Jan 2025DORA applies since
Clients includeEY, Sapiens, Rapyd, Amdocs, Intel, Roche · and more
01.

What DORA actually requires from a Copilot rollout

DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025. It covers a wide range of EU financial entities: banks, insurers, investment firms, payment institutions, crypto-asset service providers and crowdfunding platforms. It also reaches the ICT third-party providers those entities depend on, Microsoft included.

The direct answer

Is Microsoft Copilot "DORA compliant"?

No, and no software product is. DORA governs how your organisation manages ICT risk, including risk from third-party providers like Microsoft. Compliance sits with your risk process around the rollout, not with Copilot as a certified product.

For a bank or insurer that means a register entry for the Copilot contract, a concentration-risk look at how much of your stack already sits on Microsoft cloud, and (the part I actually help with) a documented staff training plan. Data residency sits in the same third-party-risk picture, worth reading next to data residency and the EU Data Boundary.

02.

Two training duties, one Copilot rollout: Article 5(4) and Article 13(6)

DORA does not leave training as a vague good idea. Article 13(6) requires financial entities to build ICT security and operational resilience training into their staff scheme, calibrated to each role's complexity. Article 5(4) adds a duty for the management body itself: members must keep their own ICT risk knowledge current through regular training, not delegate it downward. Article 5(2)(g) makes both duties real: the management body has to budget for them.

I run 3 formats, mapped onto those 2 duties. An Executive Briefing (90 minutes) gives the management body its own Article 5(4) hour, ICT risk framed around the Copilot rollout in front of them. A Lunch and Learn (60 minutes, up to 100 people, live online) covers the staff-wide awareness Article 13(6) asks for, department by department. A Team Workshop (2 hours, hands-on, up to 20 people) gives daily Copilot users the skills training that counts toward the same documented scheme.

(Calibrated to role complexity is DORA's phrase, not mine, but it happens to describe exactly how I already run these 3 formats. A teller does not need the same session as a board member.)

03.

Microsoft's own position: one of 19 designated critical ICT providers

As of September 2026: on 18 November 2025, the EU's 3 supervisory authorities (EBA, EIOPA and ESMA) jointly published their first list of critical ICT third-party providers (CTPPs) under DORA. Microsoft Ireland Operations Limited is on that list, one of 19 providers, alongside names like AWS, Google Cloud, IBM, SAP and Oracle.

The direct answer

Does Microsoft's CTPP designation change what my organisation has to do?

No. The designation puts Microsoft under direct ESA oversight, but it does not remove your own obligations. You still need your own register entry, concentration-risk assessment and staff training plan. The designation is a fact about Microsoft's status, not a substitute for your paperwork.

04.

A documented Copilot training control for financial services

If DORA is on your checklist, the real question is simple: what do I actually have to show for this? Three things, plus the sessions themselves.

01Attendance record

Names, date, format (briefing, lunch and learn or workshop) and a summary of what the session covered, kept on file as your own evidence.

02Role-calibrated training log

A record showing training matched to complexity: board members get the Briefing, daily Copilot users get the Workshop, everyone else gets the awareness session, mapped to Article 13(6).

03A short note for your Article 5(4) file

Confirmation that the management body attended its own session, dated, so the personal knowledge duty in Article 5(4) has something concrete behind it.

Bottom line: this is training built to leave a paper trail, not a certificate nobody in your audit file asked for.
05.

Who this is for

This is Copilot training for banks, insurers, investment firms and the other entities DORA covers. It's built for a compliance or risk lead with "Copilot rollout" and "DORA training" on the same spreadsheet and no line connecting them. It also fits IT or Microsoft 365 adoption leads who would rather run one programme than two, and board members who owe Article 5(4) their own hour.

For the board-level session alone, without the DORA framing, see the Executive Briefing page. This page adds the DORA documentation around it.

06.

Price and how to book

Last updated September 2026. Executive Briefing (90 minutes): from €1,820 up to €2,730. Lunch and Learn (60 minutes, up to 100 people, live online): from €1,530 up to €2,300. Team Workshop (2 hours, hands-on, up to 20 people): from €1,820 up to €2,730. Book more than one format for a larger organisation, priced the same way. The full ladder is on the live online Copilot workshops hub.

I have no commercial interest in Microsoft. I built the DORA framing around these sessions because, for a bank or an insurer, training is the part of a Copilot rollout that DORA actually expects you to document (and nobody at Microsoft asked me to).

For the same sector's hands-on Excel angle, see Copilot in Excel for Finance Teams. For the parallel obligation under a different regulation (AI literacy, not ICT risk), see the EU AI Act's Article 4 training duty.

Leave your details below with the format you have in mind (briefing, lunch and learn or workshop) and I will call you back to talk through scope, timing and your role-mix.

07.

Frequently asked questions

Is Microsoft Copilot "DORA compliant"?

No, and no software product is. DORA governs how your organisation manages its own ICT risk, including risk from providers like Microsoft. Training is a documented control inside that process, not a certification for Copilot.

Does DORA require staff training on tools like Copilot?

Yes. Article 13(6) requires ICT security and operational resilience training in the staff scheme, matched to each role's complexity, and Article 5(2)(g) requires the management body to budget for it.

Is Microsoft designated as a critical ICT third-party provider under DORA?

Yes. On 18 November 2025, the EBA, EIOPA and ESMA jointly designated Microsoft Ireland Operations Limited one of 19 critical ICT third-party providers. That puts Microsoft under direct ESA oversight. It does not remove your own register, risk assessment and training obligations.

What should we document before rolling out Copilot to staff?

At minimum: a register entry for the Copilot contract, a concentration-risk note if Copilot sits alongside other Microsoft dependencies, and a role-calibrated training plan for Article 13(6). These sessions are built to produce that last piece with evidence attached.

How is training for DORA different from a general Copilot workshop?

The Copilot content is largely the same. What changes is the documentation: who attended, on what, when, and how it maps to Article 13(6) and 5(4), so the session becomes evidence instead of a one-off event with no paper trail.

How is this different from the EU AI Act's Article 4 training?

Different regulation, different obligation. Article 4 asks for baseline AI literacy, EU-wide. DORA is narrower in sector but far more specific: a formal third-party register, concentration-risk assessment and board accountability, with training as one piece inside that framework. See the Article 4 page if you have both obligations.

Is this page legal advice?

No. Talk to your own counsel and compliance team about how DORA applies to your organisation. I build and document Copilot training, I don't practise law.

Book Copilot training for financial services

Let's build the training your DORA file is waiting for.

Leave your details and I will call you back. A first call takes 30 to 45 minutes, and by the end you will know which format fits your role-mix and roughly when we can run it. No deck, no obligation.

Updated: September 2026 · by Eyal Marcus · AI consultant and trainer, 264 sessions in 112 organisations